Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ips_policy applying to local_rules #251

Open
dougburks opened this issue Jan 26, 2017 · 1 comment
Open

ips_policy applying to local_rules #251

dougburks opened this issue Jan 26, 2017 · 1 comment

Comments

@dougburks
Copy link

Hello!

This question is related to #235.

Since the current version of PulledPork now copies rules from local_rules to rule_path, it looks like if you set an ips_policy to apply to your Snort ruleset, it will try to apply that policy to your local_rules as well. Since most local rules don't have any policy set, they are therefore disabled. For example, please see:
https://groups.google.com/d/topic/security-onion/D9BW2ttPF3Y/discussion

Is this intended behavior?

@shirkdog
Copy link
Owner

In the case you referenced, I would assume this is not intended behavior, because the engine is Suricata and not Snort, but still seems like worth investigating even for Suricata.

But having the ability to have policy in your local.rules outside of the official Talos rules for Snort sounds like something you would want, I will take a look and let you know.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants